Thursday, November 13, 2008

New trend security threat ? Clickjacking

Clickjacking ?What's that? It become one of the hot pie issue within IT security field recently, speakers will make it as one of the topic whenever any security conferences held. If you type "Clickjacking" word in google, it will return around ~700K results related to "Clickjacking".



Although this kind of threat already been identified, browsers vendors (IE, FF, Safari, Opera) still not yet have any temporarily solutions for the moments. Similarly to "jacking" techniques are onMOuseUpJacking, FormJacking, SubmitJacking.

When do some research on clickjacking, this technique try to 'foolish' user clicking behavior and it will return profitable for the web-owner by clickon loaded-advertistment. One of the characteristic for 'clickjacking' is try to hide or invisible the button as small as possible. Well, mozopacity javascript or called transparency was used to hide the images, website iframe and etc.

Example:



Some said "NoScript" add-on module can be get in Firefox can prevent from this type of attack, then how about for others browser? According to the pie-chart obtaied from http://en.wikipedia.org/wiki/Usage_share_of_web_browsers; IE browsers still dominating! The risks still out there and wild !

Although we have outstanding tools to prevent this kind of threat, the security responsibility still depend to internet users usage behavior. :(




Definition of Clickjacking can be obtained from http://en.wikipedia.org/wiki/Clickjacking

1 comments:

Cathlin said...

Share some exciting news with everyone.
I would like to share some exciting news with everyone. I recently discovered Search-and-destroy Antispyware (http://www.Search-and-destroy.com) and it’s the best scanner that I’ve used so far. It picks the same type of bugs that the better known and more expensive scans do and it’s so easy to get. The antispyware solution from Search-and-destroy is the perfect solution for taking care of your computer. I know it’s made a difference for me and I’m so glad that I gave it a try. I really believe that you will benefit from this scan as much as I have and I recommend that you give it a try.